I also took DNSQuerySniffer (NirSoft) for a spin. First impression was positive. It looks like a convenient way to focus on DNS activity. Be it for short-duration testing or longer-duration capture & save (in multiple formats). I didn't see a way to configure it to perform its own reverse lookups on the IP Addresses it sees. Which would help users to spot IP Addresses associated with parties of interest. However, it would be easy enough to script extract the addresses from one of the save file formats, do your own PTR lookups, then append your results so that they too could be found when searching the save file.